Items related to Incident Response: Investigating Computer Crime

Incident Response: Investigating Computer Crime - Softcover

 
9780072131826: Incident Response: Investigating Computer Crime
View all copies of this ISBN edition:
 
 
This is one of the first books available that explains what to do after you've been hacked. Written by FBI insiders, this book reveals the computer forensics process and offers authoritative solutions designed to counteract and conquer hacker attacks.

"synopsis" may belong to another edition of this title.

Review:
A strong system of defenses will save your systems from falling victim to published and otherwise uninventive attacks, but even the most heavily defended system can be cracked under the right conditions. Incident Response aims to teach you how to determine when an attack has occurred or is underway--they're often hard to spot--and show you what to do about it. Authors Kevin Mandia and Chris Prosise favor a tools- and procedures-centric approach to the subject, thereby distinguishing this book from others that catalog particular attacks and methods for dealing with each one. The approach is more generic, and therefore better suited to dealing with newly emerging attack techniques.

Anti-attack procedures are presented with the goal of identifying, apprehending, and successfully prosecuting attackers. The advice on carefully preserving volatile information, such as the list of processes active at the time of an attack, is easy to follow. The book is quick to endorse tools, the functionalities of which are described so as to inspire creative applications. Information on bad-guy behavior is top quality as well, giving readers knowledge of how to interpret logs and other observed phenomena. Mandia and Prosise don't--and can't--offer a foolproof guide to catching crackers in the act, but they do offer a great "best practices" guide to active surveillance. --David Wall

Topics covered: Monitoring computer systems for evidence of malicious activity, and reacting to such activity when it's detected. With coverage of Windows and Unix systems as well as non-platform-specific resources like Web services and routers, the book covers the fundamentals of incident response, processes for gathering evidence of an attack, and tools for making forensic work easier.

From the Back Cover:

Learn secrets and strategies for recovering from computer crime incidents

Respond to security breaches and hacker attacks the right way with help from this insightful and practical guide. You'll get details on the entire computer forensic process and learn the importance of following specific procedures immediately after a computer crime incident occurs. Investigate various software including UNIX, Windows NT, Windows 2000, and application servers. Packed with technical examples and loads of how-to scenarios, this book will show you how to recognize unauthorized access, uncover unusual or hidden files, and monitor Web traffic. Detailed, authoritative, and up to date--Incident Response is the only book you need.

  • Plan and prepare for all stages of an investigation--including detection, initial response, management interaction, and more
  • Learn the importance of evidence handling and storage
  • Perform a "trap and trace" and learn network protocols
  • Monitor network traffic and detect illicit servers and covert channels
  • Investigate Web server attacks, DNS attacks, and router attacks

"About this title" may belong to another edition of this title.

Other Popular Editions of the Same Title

9780072226966: Incident Response and Computer Forensics, Second Edition

Featured Edition

ISBN 10:  007222696X ISBN 13:  9780072226966
Publisher: McGraw-Hill/Osborne, 2003
Softcover

Top Search Results from the AbeBooks Marketplace

Stock Image

Prosise, Chris; Mandia, Kevin
Published by Mcgraw-Hill Osborne Media (2001)
ISBN 10: 0072131829 ISBN 13: 9780072131826
New Softcover Quantity: 1
Seller:
BennettBooksLtd
(North Las Vegas, NV, U.S.A.)

Book Description Condition: New. New. In shrink wrap. Looks like an interesting title! 2.35. Seller Inventory # Q-0072131829

More information about this seller | Contact seller

Buy New
US$ 94.06
Convert currency

Add to Basket

Shipping: US$ 5.87
Within U.S.A.
Destination, rates & speeds